Answered by:
CRM2011: claims based authentication on port 443 using a seperate ADFS server

Question
-
I managed to setup claims based authentication on our hosted environment, thnx to this great blog:
http://www.interactivewebs.com/blog/index.php/server-tips/microsoft-crm-2011-how-to-configure-ifd-hosted-setup/Now CRM2011 is available through port 444 (and 443 for ADFS), but I want to use 443 only!
According to this thread, to accomplish this I need to install ADFS on a seperate server:
http://social.microsoft.com/Forums/en/crm/thread/bc551776-e632-401f-a8b2-bd88a7eeead8But how?
In our datacenter all 3 servers (DC, SQL, CRM) are in 1 domain using 1 router for internet access. That router forwards all trafic on port 443 to the CRM server. But in this setup both ADFS server and CRM server will use port 443 and the router can only forward to 1.
It must be possible somehow since Microsoft On-line is available on port 443.
Tuesday, August 2, 2011 9:06 AM
Answers
-
If you have a router that can only do Port Address Translation (PAT) and not Network Address Translation (NAT), then I would definitely replace your router. Of course if you only have one public IP, then a new router won't help either.
Brian Bewley- Marked as answer by vip33 Wednesday, August 10, 2011 9:20 AM
Wednesday, August 10, 2011 4:56 AM
All replies
-
If you want to have running CRM2011 on the port 443 you need to have additional server for ADFS or you can try to install on SQL box (I not tried if this will work).
KG
My Dynamics CRM Blog: http://bovoweb.blogspot.comTuesday, August 2, 2011 11:39 AM -
Ehm not to be rude, but kgorcwewski, did you actually read my post?
The fact that I need an additional server for ADFS is something I wrote myself: ' to accomplish this I need to install ADFS on a seperate server'.
The question remains how this is done, 2 servers both accessible from the outside on port 443 given the fact that the router can only forward traffic on port 443 to 1 server.
Tuesday, August 2, 2011 1:00 PM -
Sorry, I misread as well. If the Router can only send to 443 on one server, you will need to keep them on one server
--Dodd- Edited by MDodd73 Tuesday, August 2, 2011 4:10 PM Misread
Tuesday, August 2, 2011 4:09 PM -
Bump
Do I need a different router then or 2 routers?
Friday, August 5, 2011 10:51 AM -
If you have a router that can only do Port Address Translation (PAT) and not Network Address Translation (NAT), then I would definitely replace your router. Of course if you only have one public IP, then a new router won't help either.
Brian Bewley- Marked as answer by vip33 Wednesday, August 10, 2011 9:20 AM
Wednesday, August 10, 2011 4:56 AM